https://docker.github.io/docker-agent/configuration/sandbox/
If, like me, you couldn't find any security-related info on the linked page.
i remember going through the entire docs of docker sandbox and there was not one mention of attack vectors. did they fix that?
Docker Agent is a harness. There is a sandbox mode that can be used to run it in docker sandbox (a VM, not a container). If you don't use sandbox mode then I assume it is running in a container.
If you don't want to use their harness then you wouldn't use docker agent and instead use their `sbx` cli to run the harness of your choice (claude, codex, pi, etc).
I think it will be great if Docker can get people used to using secure VMs. I am developing a similar project (still a work in progress): https://github.com/gregwebs/agent-vm